The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to conduct ARP poisoning attacks via crafted packets.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/80284http://www.reactionpenetrationtesting.co.uk/forescout-nac-icmp-arp.htmlhttp://www.securityfocus.com/bid/56689http://osvdb.org/87895